AWS IAM Interview Questions (Top 100 Questions with Answers)
Master AWS IAM Interview Questions with production-oriented questions covering IAM Users, Groups, Roles, Policies, STS, Federation, MFA, Identity Center, Permission Boundaries, SCPs, Cross-Account Access, Security Best Practices, and real-world production scenarios.
Module Navigation
Previous: AWS VPC QA | Parent: AWS Learning Path | Next: AWS Lambda QA
Introduction
AWS Identity and Access Management (IAM) is the foundation of AWS security.
Almost every AWS service integrates with IAM.
Interviewers expect every AWS engineer to understand
- Authentication
- Authorization
- Least Privilege
- IAM Roles
- Temporary Credentials
- Cross Account Access
- Federation
- Security Best Practices
This guide contains the Top 100 AWS IAM Interview Questions frequently asked in
- AWS Solution Architect
- Cloud Engineer
- DevOps Engineer
- Platform Engineer
- Security Engineer
- Java Developer
AWS IAM Learning Roadmap
IAM Basics
│
▼
Users
│
▼
Groups
│
▼
Policies
│
▼
Roles
│
▼
STS
│
▼
Federation
│
▼
Cross Account
│
▼
Production Security
IAM Fundamentals
1. What is AWS IAM?
AWS Identity and Access Management (IAM) is the service used to securely control access to AWS resources.
2. Why use IAM?
- Authentication
- Authorization
- Fine-Grained Permissions
- Security
- Auditability
3. Is IAM Global or Regional?
IAM is a global AWS service.
4. What problems does IAM solve?
- Unauthorized Access
- Credential Management
- Access Control
- Temporary Access
5. What are IAM Components?
- Users
- Groups
- Roles
- Policies
IAM Users
6. What is an IAM User?
Represents a person or application requiring long-term AWS credentials.
7. What credentials can an IAM User have?
- Password
- Access Key
- Secret Key
8. Should applications use IAM Users?
No.
Applications should use IAM Roles whenever possible.
9. Root User vs IAM User?
| Root User | IAM User |
|---|---|
| Full Account Access | Limited Permissions |
| One per Account | Multiple Users |
| Avoid Daily Use | Daily Operations |
10. Best Practice for Root User?
- Enable MFA
- Avoid daily usage
- Never create access keys unless absolutely required
IAM Groups
11. What is an IAM Group?
A collection of IAM Users.
12. Why Groups?
Simplifies permission management.
13. Can Groups contain Groups?
No.
14. Can one User belong to multiple Groups?
Yes.
15. Do Groups have credentials?
No.
IAM Policies
16. What is an IAM Policy?
JSON document defining permissions.
17. Policy Components?
- Effect
- Action
- Resource
- Condition
18. Effect?
Allow
or
Deny.
19. Action?
AWS API operations.
Example
s3:GetObject
20. Resource?
AWS resource ARN.
21. Condition?
Additional access rules.
22. Managed Policy?
Created and maintained by AWS or customers.
23. Inline Policy?
Attached directly to a single principal.
24. Customer Managed Policy?
Reusable custom policy.
25. AWS Managed Policy?
Maintained by AWS.
IAM Roles
26. What is an IAM Role?
An identity with temporary credentials assumed by trusted entities.
27. Why Roles?
Avoid long-term credentials.
28. EC2 Role?
Allows EC2 to access AWS services securely.
29. Lambda Role?
Allows Lambda functions to access AWS resources.
30. ECS Task Role?
Provides permissions to containers.
31. EKS IAM Role?
Grants Kubernetes workloads access to AWS services.
32. Cross Account Role?
Allows secure access between AWS accounts.
33. Can Roles have passwords?
No.
34. Can Users assume Roles?
Yes.
35. Trust Policy?
Defines who can assume a role.
IAM Security
36. Principle of Least Privilege?
Grant only required permissions.
37. Explicit Deny?
Overrides Allow.
38. MFA?
Multi-Factor Authentication.
39. Password Policy?
Controls password complexity and rotation.
40. Credential Report?
Lists IAM credential status.
AWS STS
41. What is AWS STS?
Security Token Service.
Provides temporary credentials.
42. Benefits?
- Temporary Access
- Cross Account
- Federation
43. AssumeRole?
Generates temporary credentials.
44. Temporary Credentials?
Expire automatically.
45. Why STS?
Improves security by eliminating long-term credentials.
Federation
46. What is Federation?
Allows external identity providers to access AWS.
47. Supported Providers?
- Active Directory
- SAML
- OIDC
- Microsoft Entra ID (Azure AD)
48. AWS IAM Identity Center?
Centralized workforce access management for AWS accounts and applications.
49. SAML?
Enterprise Single Sign-On protocol.
50. OIDC?
Modern authentication protocol.
Cross Account Access
51. Cross Account Access?
Uses IAM Roles.
52. Why Cross Account?
Secure multi-account architecture.
53. Resource Policy vs IAM Policy?
IAM Policies attach to identities.
Resource Policies attach to resources.
54. S3 Bucket Policy?
Resource Policy.
55. KMS Key Policy?
Resource Policy.
Permission Boundaries
56. What are Permission Boundaries?
Maximum permissions an IAM principal can receive.
57. Why use Permission Boundaries?
Delegate administration safely.
58. Can Boundaries grant access?
No.
They only limit permissions.
59. Boundary vs SCP?
Boundary limits IAM principal.
SCP limits AWS account.
60. Production Use?
Large enterprises.
Organizations
61. What is AWS Organizations?
Service to centrally manage AWS accounts.
62. Service Control Policy (SCP)?
Maximum permission boundary for AWS accounts.
63. SCP vs IAM Policy?
SCP controls account limits.
IAM controls identities.
64. Can SCP grant permissions?
No.
Only restricts permissions.
65. Production Benefits?
Central governance.
Production Scenarios
66. Developer accidentally deleted production resources.
Use least privilege and separate production roles.
67. Access Key leaked.
Immediately
- Disable key
- Rotate credentials
- Review CloudTrail
68. EC2 cannot access S3.
Check IAM Role.
69. Lambda Access Denied.
Verify execution role permissions.
70. Cross Account access fails.
Check Trust Policy and IAM permissions.
71. Public S3 bucket detected.
Review Bucket Policy and IAM permissions.
72. Too many administrators.
Implement role-based access.
73. Temporary contractor access.
Use IAM Role with expiration.
74. Employees leaving company.
Disable IAM User or revoke federation access immediately.
75. Compliance audit.
Generate IAM Credential Report.
Monitoring
76. CloudTrail?
Tracks IAM API activity.
77. IAM Access Analyzer?
Identifies unintended access.
78. IAM Last Accessed?
Shows when permissions were last used.
79. AWS Config?
Monitors IAM configuration changes.
80. GuardDuty?
Detects suspicious IAM activity.
Architect Questions
81. Secure AWS Account?
- MFA
- Least Privilege
- IAM Roles
- CloudTrail
- SCP
82. Multi-Account Security?
Use AWS Organizations.
83. IAM for Microservices?
Separate IAM Roles for each service.
84. Secrets Management?
AWS Secrets Manager.
85. Secure CI/CD?
IAM Roles
No static credentials.
Senior Interview Questions
86. IAM User vs Role?
Users have long-term credentials.
Roles use temporary credentials.
87. Managed Policy vs Inline Policy?
Managed policies are reusable.
Inline policies are tied to one identity.
88. IAM Policy Evaluation Order?
AWS evaluates all applicable policies.
Any explicit Deny overrides all Allows.
89. Common IAM mistakes?
- Wildcard permissions
- Root account usage
- Static credentials
- Missing MFA
90. IAM Best Practices?
- Least Privilege
- Roles
- MFA
- Rotation
- Monitoring
91. ARN?
Amazon Resource Name.
Unique resource identifier.
92. IAM Condition Keys?
Used to restrict access based on context.
Example
- IP Address
- MFA
- Time
93. Session Policies?
Further restrict permissions during AssumeRole sessions.
94. Policy Simulator?
Tests IAM policies before deployment.
95. Access Advisor?
Shows service access history.
96. Permission Sets?
Used by IAM Identity Center to assign permissions.
97. What should be monitored?
- Failed Logins
- Access Key Usage
- Role Assumptions
- Policy Changes
98. Production Readiness Checklist?
- MFA Enabled
- Least Privilege
- IAM Roles
- CloudTrail
- Access Analyzer
- Credential Rotation
99. What do interviewers expect?
- IAM Architecture
- Security Knowledge
- Production Best Practices
- Troubleshooting Skills
100. How should you prepare?
- Create IAM Users
- Configure Groups
- Build Custom Policies
- Create Roles
- Practice Cross-Account Access
- Configure IAM Identity Center
IAM Architecture
Users
│
IAM Identity Center
│
┌──────────────┴──────────────┐
▼ ▼
IAM Users IAM Roles
│ │
▼ ▼
IAM Groups STS AssumeRole
│ │
└──────────────┬──────────────┘
▼
IAM Policies
│
▼
AWS Resources
(S3, EC2, RDS, Lambda)
IAM Policy Evaluation Flow
User Request
│
▼
Authentication
│
▼
Evaluate SCP
│
▼
Evaluate Permission Boundary
│
▼
Evaluate IAM Policy
│
▼
Evaluate Resource Policy
│
▼
Any Explicit Deny?
│ │
Yes No
│ │
Deny Allow if
Permission Exists
Quick Revision
| Topic | Key Point |
|---|---|
| IAM | Identity Management |
| User | Long-Term Identity |
| Group | Collection of Users |
| Role | Temporary Identity |
| Policy | Permission Document |
| STS | Temporary Credentials |
| MFA | Multi-Factor Authentication |
| SCP | Organization-Level Restriction |
| IAM Identity Center | Workforce SSO |
| Least Privilege | Minimum Required Access |
Interview Tips
During AWS IAM interviews:
- Clearly explain the difference between Users, Groups, Roles, and Policies.
- Understand IAM Roles for EC2, Lambda, ECS, and EKS.
- Explain STS, AssumeRole, and temporary credentials.
- Know the difference between IAM Policies, Resource Policies, Permission Boundaries, and SCPs.
- Discuss IAM Identity Center, Federation, SAML, and OIDC.
- Mention production best practices such as MFA, least privilege, CloudTrail, IAM Access Analyzer, and avoiding long-term credentials.
Summary
AWS IAM is the security foundation of every AWS environment. Strong IAM interview performance requires understanding authentication, authorization, Users, Groups, Roles, Policies, STS, IAM Identity Center, Federation, Cross-Account Access, Permission Boundaries, Service Control Policies, and production security best practices.
Mastering these 100 AWS IAM interview questions prepares you for AWS Cloud Engineer, DevOps Engineer, Security Engineer, Platform Engineer, Site Reliability Engineer, and Solution Architect interviews.